geotools records
5 published records for vendor geotools.
Researcher profile
- Entered KEV
- 1 · 20%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 2
- With a fix record
- 80%
- Median publish → KEV
- 14 days
Recurring classes
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')2
- CWE-20 Improper Input Validation1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2024-36401Weaponized | Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoservergeoserver · geoserver · CWE-95 | Critical9.8 | KEV | 99.8% | Jul 1, 2024 |
62This week | CVE-2024-36404Proof of concept | GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressionsgeotools · geotools · CWE-95 | Critical9.8 | — | 76.1% | Jul 2, 2024 |
49Plan | CVE-2025-30220Proof of concept | GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handlinggeotools · geotools · CWE-611 | Critical9.1 | — | 42.3% | Jun 10, 2025 |
39Monitor | CVE-2023-25158No exploit | Unfiltered SQL Injection in Geotoolsgeotools · geotools · CWE-89 | Critical9.8 | — | 1.1% | Feb 21, 2023 |
29Monitor | CVE-2022-24818Proof of concept | Unchecked JNDI lookups in GeoToolsgeotools · geotools · CWE-20 | High7.2 | — | 2.4% | Apr 13, 2022 |
- CVE-2024-3640199Now
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
CriticalCVSS 9.8KEVWeaponizedEPSS 100%geoserver · geoserverJul 1, 2024
- CVE-2024-3640462This week
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
CriticalCVSS 9.8Proof of conceptEPSS 76%geotools · geotoolsJul 2, 2024
- CVE-2025-3022049Plan
GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
CriticalCVSS 9.1Proof of conceptEPSS 42%geotools · geotoolsJun 10, 2025
- CVE-2023-2515839Monitor
Unfiltered SQL Injection in Geotools
CriticalCVSS 9.8No exploitEPSS 1%geotools · geotoolsFeb 21, 2023
- CVE-2022-2481829Monitor
Unchecked JNDI lookups in GeoTools
HighCVSS 7.2Proof of conceptEPSS 2%geotools · geotoolsApr 13, 2022